CBRS-006 — Behavior Before Identity
Todd Kirton · Zenodo (CERN European Organization for Nuclear Research) · 2026
Security architectures are often described as though identity must be resolved before meaningful security decisions can begin. Operational practice is less orderly. Session monitoring, Zero Trust policy engines, intrusion detection, and industrial monitoring all evaluate behavioral or contextual evidence while activity is occurring. This paper examines that ordering problem and argues that observed behavior can support detection and proportionate, reversible responses before the attribution needed for the next security decision is complete. Behavior also remains relevant after an identity has been authenticated or otherwise recognized. Behavior, however, is not an identity mechanism. Anomaly is not proof of compromise, familiar-looking activity is not proof of legitimacy, and behavioral evidence is often meaningful only when combined with role, asset, resource, process, historical, or threat context. Behavioral references also differ materially: explicit rules and allowlists, statistical profiles, and learned models do not share identical failure modes. This paper therefore proposes a graduated-response principle in which the evidence burden rises with uncertainty, consequence, irreversibility, and the need for actor-specific accountability. The resulting architecture is one of evidence ordering: security may sometimes need to answer what is happening before it can fully answer who is responsible.